CWE-307: CWE-307

174
Total CVEs
68
Critical
70
High
8.1
Avg CVSS

Yearly Trend

2026
14
2025
57
2024
36
2023
33
2022
9

Top Affected Vendors

1 Ibm 9
2 Dell 7
3 Nextcloud 4
4 Fortinet 3
5 Schneider Electric 3
6 Endress 3
7 Gl Inet 3
8 Siemens 2
9 Moodle 2
10 Dlink 2

All CWE-307 CVEs (174)

CVE-2026-24436
9.8

This vulnerability allows attackers to perform unlimited brute-force attacks against administrative credentials on Tenda W30E V2 routers. Attackers ca...

Jan 26, 2026
CVE-2025-64310
9.8

This vulnerability allows attackers to brute-force administrative passwords on EPSON projector web interfaces due to lack of rate limiting. Attackers ...

Nov 21, 2025
CVE-2025-63807
9.8

This vulnerability allows unauthenticated attackers to brute-force verification codes due to weak generation and missing rate limiting. Successful exp...

Nov 20, 2025
CVE-2025-64102
9.8

Zitadel identity infrastructure software versions prior to 4.6.0, 3.4.3, and 2.71.18 are vulnerable to online brute-force attacks on OTP, TOTP, and pa...

Oct 29, 2025
CVE-2025-56221
9.8

CVE-2025-56221 is an authentication bypass vulnerability in SigningHub v8.6.8 that allows attackers to brute force login credentials due to insufficie...

Oct 17, 2025
CVE-2025-8679
9.8

This vulnerability allows attackers to bypass captive portal authentication in ExtremeGuest Essentials by performing repeated manual login attempts. U...

Oct 1, 2025
CVE-2025-1740
9.8

CVE-2025-1740 is an authentication bypass vulnerability in Akinsoft MyRezzta software that allows attackers to bypass authentication mechanisms, explo...

Sep 3, 2025
CVE-2025-7393
9.8

This vulnerability in Drupal Mail Login modules allows attackers to perform unlimited authentication attempts without rate limiting, enabling brute fo...

Jul 21, 2025
CVE-2024-9342
9.8

CVE-2024-9342 allows attackers to perform unlimited brute-force login attempts against Eclipse GlassFish servers, potentially compromising administrat...

Jul 16, 2025
CVE-2025-43863
9.8

This vulnerability in vantage6 allows attackers with authenticated access to brute-force user passwords through unlimited attempts at the change passw...

Jun 12, 2025
CVE-2025-25595
9.8

CVE-2025-25595 is an authentication bypass vulnerability in Safe App version a3.0.9 that allows attackers to brute force login credentials due to miss...

Mar 18, 2025
CVE-2024-5716
9.8

CVE-2024-5716 is an authentication bypass vulnerability in Logsign Unified SecOps Platform that allows remote attackers to reset user passwords withou...

Nov 22, 2024
CVE-2024-51558
9.8

This vulnerability allows remote attackers to bypass authentication protections in Wave 2.0 by brute-forcing OTP, MPIN, or password credentials due to...

Nov 4, 2024
CVE-2024-47656
9.8

This vulnerability in Shilpi Client Dashboard allows remote attackers to bypass login attempt restrictions and perform brute force attacks against use...

Oct 4, 2024
CVE-2024-41276
9.8

This vulnerability allows attackers to bypass PIN code authentication in Kaiten by exploiting weak request limiting mechanisms. Attackers can brute-fo...

Oct 1, 2024
CVE-2024-47088
9.8

This vulnerability allows remote attackers to bypass OTP authentication through brute force attacks on the Apex Softcell LD Geo API login. Attackers c...

Sep 19, 2024
CVE-2024-45790
9.8

This vulnerability allows remote attackers to perform brute force attacks against user passwords in Reedos aiM-Star version 2.0.1 due to missing rate ...

Sep 11, 2024
CVE-2024-43042
9.8

Pluck CMS 4.7.18 lacks rate limiting on login attempts, allowing attackers to perform brute force attacks against admin credentials. This affects all ...

Aug 16, 2024
CVE-2024-42465
9.8

This vulnerability allows attackers to perform unlimited authentication attempts against upKeeper Manager, enabling brute-force attacks to guess crede...

Aug 16, 2024
CVE-2024-39225
9.8

This CVE describes a remote code execution vulnerability in multiple GL-iNet router models that allows attackers to bypass authentication mechanisms a...

Aug 6, 2024
CVE-2024-21652
9.8

This critical vulnerability in Argo CD allows attackers to bypass brute force login protection by exploiting a chain of flaws including a Denial of Se...

Mar 18, 2024
CVE-2024-2051
9.8

This CVE describes an authentication brute-force vulnerability in Schneider Electric systems where attackers can make unlimited login attempts without...

Mar 18, 2024
CVE-2023-6928
9.8

This vulnerability allows attackers to perform unlimited password guessing attacks against EuroTel ETL3100 devices, potentially gaining administrative...

Dec 19, 2023
CVE-2023-6272
9.8

The Theme My Login 2FA WordPress plugin before version 1.2 lacks rate limiting on two-factor authentication validation attempts, allowing attackers to...

Dec 18, 2023
CVE-2023-49443
9.8

DoraCMS v2.1.8 has a critical authentication vulnerability where the same verification code is reused for both username and password validation. This ...

Dec 8, 2023
CVE-2023-35039
9.8

This vulnerability allows attackers to perform unlimited authentication attempts against the WordPress Password Reset with Code plugin's REST API, ena...

Dec 7, 2023
CVE-2023-24051
9.8

CVE-2023-24051 is a client-side rate limiting vulnerability in Connectize AC21000 G6 routers that allows attackers to bypass authentication controls v...

Dec 4, 2023
CVE-2023-2675
9.8

This vulnerability allows attackers to perform unlimited authentication attempts against Twake instances, enabling brute-force attacks to guess user c...

Nov 7, 2023
CVE-2023-27152
9.8

CVE-2023-27152 is an authentication bypass vulnerability in DECISO OPNsense firewall software that allows attackers to perform unlimited brute-force l...

Oct 23, 2023
CVE-2023-40834
9.8

OpenCart CMS v4.0.2.2 lacks rate limiting on its login page, allowing unauthenticated attackers to perform brute force attacks against administrator p...

Sep 12, 2023
CVE-2023-21709
9.8

CVE-2023-21709 is a critical elevation of privilege vulnerability in Microsoft Exchange Server that allows authenticated attackers to gain SYSTEM-leve...

Aug 8, 2023
CVE-2023-32224
9.8

This vulnerability in D-Link DSL-224 routers allows attackers to bypass authentication through brute-force attacks due to insufficient rate limiting. ...

Jun 28, 2023
CVE-2023-3173
9.8

CVE-2023-3173 is an authentication brute-force vulnerability in froxlor web hosting control panel. Attackers can bypass rate limiting to perform unlim...

Jun 9, 2023
CVE-2023-2531
9.8

This vulnerability allows attackers to perform unlimited authentication attempts against AzuraCast instances, enabling brute-force attacks to guess va...

May 5, 2023
CVE-2022-2525
9.8

CVE-2022-2525 is an authentication brute-force vulnerability in Calibre-Web that allows attackers to make unlimited login attempts without rate limiti...

Apr 15, 2023
CVE-2023-1665
9.8

This vulnerability allows attackers to perform unlimited authentication attempts against Twake instances, enabling brute-force attacks to guess user c...

Mar 27, 2023
CVE-2022-22487
9.8

CVE-2022-22487 allows remote attackers to perform brute force attacks against IBM Spectrum Protect storage agents because administrative login attempt...

Jun 30, 2022
CVE-2022-31273
9.8

This vulnerability allows attackers to perform brute-force attacks against TopIDP3000 Topsec Operating System by manipulating the session_id cookie. A...

Jun 14, 2022
CVE-2021-43958
9.8

CVE-2021-43958 allows remote attackers to brute force user credentials in Atlassian Fisheye and Crucible by bypassing CAPTCHA protection on REST endpo...

Mar 16, 2022
CVE-2022-22810
9.8

This vulnerability allows attackers to perform unlimited authentication attempts against admin interfaces of Schneider Electric smart home controllers...

Feb 9, 2022
CVE-2020-21237
9.8

This vulnerability in LJCMS v1.11 allows attackers to perform brute force attacks against the user login box, potentially hijacking user accounts. Any...

Dec 27, 2021
CVE-2021-37934
9.8

This vulnerability allows unauthenticated remote attackers to perform unlimited login attempts against Huntflow Enterprise's authentication endpoint, ...

Dec 10, 2021
CVE-2021-41435
9.8

This vulnerability allows remote attackers to bypass CAPTCHA-based brute-force protection on affected ASUS routers, enabling unlimited login attempts....

Nov 19, 2021
CVE-2021-28909
9.8

This vulnerability allows unauthenticated attackers to perform brute force attacks against the login service of BAB TECHNOLOGIE GmbH eibPort V3 device...

Sep 9, 2021
CVE-2021-28911
9.8

Unauthenticated attackers can access the /tmp directory in BAB TECHNOLOGIE GmbH eibPort V3 devices prior to version 3.9.1, exposing sensitive data lik...

Sep 9, 2021
CVE-2020-18698
9.8

This vulnerability allows remote attackers to perform unlimited brute force login attempts against Lin-CMS-Flask without any rate limiting or account ...

Aug 16, 2021
CVE-2021-32522
9.8

This vulnerability allows remote attackers to perform brute force attacks against QSAN storage management systems due to insufficient authentication a...

Jul 7, 2021
CVE-2021-22915
9.8

This vulnerability allows attackers to bypass Nextcloud's brute-force protection by using IPv6 addresses, which weren't included in rate-limiting calc...

Jun 11, 2021
CVE-2021-22737
9.8

This vulnerability in Schneider Electric homeLYnk and spaceLYnk systems allows attackers to discover credentials through brute force attacks, leading ...

May 26, 2021
CVE-2019-18235
9.8

This vulnerability in Advantech Spectre RT ERT351 routers allows attackers to bypass authentication through brute-force password attacks due to insuff...

Mar 17, 2021

About CWE-307 (CWE-307)

Our database tracks 174 CVEs classified as CWE-307, with 68 rated critical and 70 rated high severity. The average CVSS score for CWE-307 vulnerabilities is 8.1.

External reference: View CWE-307 on MITRE CWE →

Monitor CWE-307 Vulnerabilities

Get alerted when new CWE-307 CVEs affect your infrastructure.

Start Monitoring Free